EC2 Grouper Campaign (Campaign)
ID: 51add7c6-5990-5bde-9c95-f7c8e4c88a2a
STIX ID: report--51add7c6-5990-5bde-9c95-f7c8e4c88a2a
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-12-30
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
The report describes the EC2 Grouper threat actor active in cloud environments: they use AWS PowerShell tooling with distinctive (recently modified) user agents, create security groups with predictable names like `ec2group`/`ec2group12345` via `CreateSecurityGroup`, and perform automated reconnaissance (`DescribeInstanceTypes`, `DescribeRegions`, `DescribeVpcs`) followed by actions such as `RunInstances` and occasional VPC/internet-gateway creation; resource hijacking is suspected but not confirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
